flux-controller-patch-releases

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources to generate release artifacts, which could potentially be used to inject instructions into the agent's context.
  • Ingestion points: The skill fetches PR titles, descriptions, and repository metadata via gh pr view and gh api (Step 3 and "How To Build The Changelog Entry" section).
  • Boundary markers: The skill does not define specific delimiters or warnings to ignore instructions embedded in the external PR data.
  • Capability inventory: The skill has the ability to modify repositories (git commit, git tag), perform network operations (git push, gh api), and manage PR lifecycles (gh pr merge).
  • Sanitization: There is no evidence of filtering or sanitizing PR metadata before it is interpolated into commit messages or changelog files.
  • [COMMAND_EXECUTION]: The skill executes a wide range of shell commands to automate the release workflow.
  • It utilizes git for branch management, tagging, and code updates.
  • It utilizes the GitHub CLI (gh) for PR tracking, status polling, and API interactions, including background monitoring loops for CI and approvals.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:39 PM
Security Audit — agent-trust-hub — flux-controller-patch-releases